Latest CVE Feed
-
5.4
MEDIUMCVE-2025-26765
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.... Read more
Affected Products :- Published: Feb. 16, 2025
- Modified: Feb. 16, 2025
- Vuln Type: Authorization
-
5.4
MEDIUMCVE-2023-32536
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authenticat... Read more
Affected Products : apex_central- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-32604
Affected versions Trend Micro Apex Central (on-premise) are vulnerable to potential authenticated reflected cross-site scripting (XSS) attacks due to user input validation and sanitization issues. Please note: an attacker must first obtain authenticat... Read more
Affected Products : apex_central- Published: Jun. 26, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-26274
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-34837
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary code via a vulnerable parameter GrpPath.... Read more
Affected Products : escan_management_console- Published: Jun. 27, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3331
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N... Read more
- Published: Jun. 28, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-51330
PHPJabbers Cinema Booking System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in Now Showing menu "date" parameter.... Read more
Affected Products : cinema_booking_system- Published: Feb. 20, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-51337
PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index.... Read more
Affected Products : event_ticketing_system- Published: Feb. 20, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-36223
Cross Site Scripting vulnerability in mlogclub bbs-go v. 3.5.5. and before allows a remote attacker to execute arbitrary code via a crafted payload to the announcements parameter in the settings function.... Read more
Affected Products : bbs-go- Published: Jul. 03, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-30322
Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to execute arbitrary code.... Read more
Affected Products : chatengine- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37122
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.... Read more
Affected Products : bagecms- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-37133
A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.... Read more
Affected Products : eyoucms- Published: Jul. 06, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-3538
A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The att... Read more
Affected Products : photo_gallery_php- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-29998
A Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject arbitrary web script or HTML and gain privileges via the description parameter.... Read more
Affected Products : g3w-suite- Published: Jul. 07, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-2964
The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.... Read more
Affected Products : simple_iframe- Published: Jul. 10, 2023
- Modified: Apr. 23, 2025
-
5.4
MEDIUMCVE-2023-37658
fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS... Read more
Affected Products : fast-poster- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUM- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2023-38350
PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.... Read more
Affected Products : pnp4nagios- Published: Jul. 15, 2023
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2025-25916
wuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.... Read more
Affected Products : wuzhicms- Published: Feb. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2023-2579
The InventoryPress WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : inventorypress- Published: Jul. 17, 2023
- Modified: Nov. 21, 2024